Security & MFA

Opally takes security seriously. This page covers authentication, multi-factor authentication, and security best practices.

Authentication

Email & Password

New users sign up with:

  1. Email address

  2. Password (minimum 8 characters)

  3. Accept Terms of Service and Privacy Policy

Multi-Factor Authentication (MFA)

Opally supports MFA for additional account security:

  1. Go to Settings > Profile tab

  2. Find the Security section

  3. Click Enable MFA

  4. Scan the QR code with an authenticator app

  5. Enter the verification code

  6. Save backup codes

Recommended: Enable MFA for all admin accounts.

Supported Authenticator Apps

  • Google Authenticator

  • Microsoft Authenticator

  • Authy

  • 1Password

  • Any TOTP-compatible app

MFA Backup Codes

When enabling MFA, you'll receive backup codes. Store these securely – they're needed if you lose access to your authenticator app.

Data Security

Encryption

  • All data is encrypted in transit (TLS 1.3)

  • Sensitive data is encrypted at rest (AES-256-GCM)

  • API keys and tokens are stored securely

OAuth Integrations

Email integrations (Gmail, Outlook) use OAuth 2.0:

  • Opally never sees your email password

  • You can revoke access at any time

  • Permissions are minimal and specific

Data Retention

  • Conversation data is retained as configured

  • You can request data deletion

  • See our Privacy Policy for details

Security Best Practices

For Admins

  1. Enable MFA – Protect admin accounts with multi-factor authentication

  2. Review access regularly – Remove users who no longer need access

  3. Use strong passwords – Enforce password requirements

  4. Limit admin accounts – Only give admin access when necessary

For All Users

  1. Don't share credentials – Each user should have their own account

  2. Use unique passwords – Don't reuse passwords from other sites

  3. Report suspicious activity – Contact your admin if something seems wrong

  4. Log out on shared devices – Always log out when done

Compliance

Opally is designed with compliance in mind:

  • GDPR-compliant data handling

  • Data processing agreements available

  • Secure infrastructure on major cloud providers

Reporting Security Issues

If you discover a security vulnerability:

  • Email: info@opally.com

  • Include details about the issue

  • Don't disclose publicly until resolved

We take all reports seriously and will respond promptly.

Last updated